Skip to content

fix(ui): encode publisher-controlled URLs for href attribute context - #1248

Merged
rdimitrov merged 1 commit into
mainfrom
fix/ui-href-attribute-encoding
May 4, 2026
Merged

rdimitrov merged 1 commit into
mainfrom
fix/ui-href-attribute-encoding

Conversation

@rdimitrov

Copy link
Copy Markdown
Member

The catalogue page interpolates publisher-supplied URL fields
(server.repository.url, server.websiteUrl) inside href="..."
attributes via innerHTML, escaping them with a textContent→innerHTML
helper. Per the HTML5 fragment-serialisation algorithm, that round-trip
encodes only &, <, >, and U+00A0 inside text nodes — it does not
encode " or '. The helper is therefore safe in element-text
contexts (where it is used for name, version, description, etc.)
but unsafe inside an attribute value.

Add an attribute-safe escapeAttr helper that follows the OWASP
attribute-encoding rule (also encodes " and ') and use it for the
two href interpolations. Element-text usages keep the existing
escapeHtml and remain unchanged. A short comment on each helper
documents the contexts they cover so future fields are wired up
correctly.

Co-Authored-By: Claude Opus 4.7 (1M context) [email protected]

The catalogue page interpolates publisher-supplied URL fields
(`server.repository.url`, `server.websiteUrl`) inside `href="..."`
attributes via `innerHTML`, escaping them with a `textContent`→`innerHTML`
helper. Per the HTML5 fragment-serialisation algorithm, that round-trip
encodes only `&`, `<`, `>`, and U+00A0 inside text nodes — it does not
encode `"` or `'`. The helper is therefore safe in element-text
contexts (where it is used for `name`, `version`, `description`, etc.)
but unsafe inside an attribute value.

Add an attribute-safe `escapeAttr` helper that follows the OWASP
attribute-encoding rule (also encodes `"` and `'`) and use it for the
two `href` interpolations. Element-text usages keep the existing
`escapeHtml` and remain unchanged. A short comment on each helper
documents the contexts they cover so future fields are wired up
correctly.

Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>
@rdimitrov
rdimitrov merged commit fbfd63c into main May 4, 2026
5 checks passed
@rdimitrov
rdimitrov deleted the fix/ui-href-attribute-encoding branch May 4, 2026 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant